SurfPhoto Marketplace — Privacy Policy
Effective date: [YYYY-MM-DD]
This Privacy Policy explains how SurfPhoto Marketplace ("we", "our", "the Platform") collects, uses, and protects your data.
1. Data We Collect
- Account information: email address, username, password (hashed).
- Uploader information: payout details handled via Stripe Connect; we do not store your bank or card data.
- Uploads: photos and listing metadata (title, description, price).
- Purchase records: transaction ID, buyer ID, photo ID, timestamp.
- Logs: IP address, user agent, basic activity logs for security.
2. What We Don't Collect
- We do not store or process full payment card data. All payments are handled securely by Stripe.
- We do not store GPS location data in photos (EXIF metadata is stripped from downloads).
3. How We Use Data
- To operate the Platform (publish photos, process purchases, manage payouts).
- To enforce our Terms of Service and Content Policy.
- To respond to support requests and reports.
- To comply with legal obligations (fraud prevention, reporting).
4. Sharing of Data
- With Stripe for payment processing and payouts.
- With service providers necessary to run the Platform (e.g., hosting, moderation tools).
- If required by law or to protect rights/safety.
5. Data Retention
- Account data is kept while your account is active.
- Purchase and payout records may be retained for up to 7 years as required by tax law.
- You may request deletion of your account at any time (we may need to retain some records for legal compliance).
6. Your Rights (GDPR/EEA/UK)
- Access: request a copy of your data.
- Rectification: request correction of inaccurate data.
- Deletion: request account deletion (subject to legal holds).
- Portability: request export of your data in portable format.
7. Cookies
- MVP: minimal cookies (session cookies only).
- If we add analytics or tracking cookies, we will update this policy and provide a consent banner.
8. Security
- Passwords stored hashed and salted.
- Signed, time-limited links used for photo downloads.
- Regular monitoring for abuse.
9. Contact
- Email: [support@my.domain]
Last Updated: January 24, 2025